Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Summary

Fortinet has released patches for critical vulnerabilities affecting its FortiMonitorOnSight product and a Chrome extension. These unauthenticated bugs allow attackers to bypass authentication and proxy user browser traffic.

IFF Assessment

FOE

The discovery and exploitation of critical vulnerabilities that allow for authentication bypass and traffic proxying represent a significant threat to organizations using the affected Fortinet products.

Severity

9.0 Critical (AI Estimated)

The vulnerabilities allow for authentication bypass and proxying of user traffic without authentication, indicating a high attack complexity and significant impact on confidentiality and integrity.

Defender Context

Defenders should prioritize patching these critical vulnerabilities in Fortinet's FortiMonitorOnSight and associated Chrome extensions immediately. Unpatched systems are at high risk of unauthorized access and traffic manipulation, potentially leading to further compromise.

Read Full Story →